Try our new research platform with insights from 80,000+ expert users

RSA Archer vs Tenable Lumin comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

RSA Archer
Ranking in IT Vendor Risk Management
4th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
42
Ranking in other categories
GRC (1st), IT Governance (1st)
Tenable Lumin
Ranking in IT Vendor Risk Management
19th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of February 2026, in the IT Vendor Risk Management category, the mindshare of RSA Archer is 6.9%, down from 11.2% compared to the previous year. The mindshare of Tenable Lumin is 1.9%, up from 1.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Vendor Risk Management Market Share Distribution
ProductMarket Share (%)
RSA Archer6.9%
Tenable Lumin1.9%
Other91.2%
IT Vendor Risk Management
 

Featured Reviews

IMRAN ALMARZOOQI - PeerSpot reviewer
Head OT Risk Management & Compliance at Abu Dhabi National Oil Company
Automates compliance management effectively but needs improved interface and dashboards
The tool basically automates whatever processes you already have, so I cannot specify improvements in that regard. However, my main issue with Archer is the graphics. The graphics have always been lacking. I always need to depend on another tool to read information from Archer to have better dashboards. It is like using Linux, and it has a Linux mindset and interface. I want to use Archer for top management and CEOs, but it looks too technical, and the dashboards are not really friendly. They are bulky, like opening an old Nintendo system from nineteen-ninety. The management agrees that Archer lacks in terms of presentation and dashboarding. It is complex, not user-friendly, and bulky. The interface just looks old.
Yusuf-Hashmi - PeerSpot reviewer
Sr. Director - Group Head - IT Security (CISO) at Jubilant Organosys Ltd., India, Leading Chemical M
It creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks
Tenable Lumin's dashboard helps me understand my vulnerabilities and which tasks I should prioritize for vulnerability remediation. Tenable creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks. Real-time threat intelligence is also helpful. They get multiple sources of intelligence and correlate the data. Lumin discovers your assets through an agent or a network scan. That's an excellent feature that I'm leveraging now to better understand where all my assets are.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Solution is scalable."
"The most valuable features are the advanced workflow and the dashboards. This tool can present data wonderfully to management, and it is easy for them to manage the risk plans."
"First of all, its access control feature where it provides application level access, solution level access, and even recall access, as well."
"Archer has simplified our security audits. It's made it easier to raise and trigger questionnaires to customers."
"Its user interface is pretty neat, and there is flexibility in generating the data. You can customize reports at any level. You can directly get reports in Tableau format. If you want to generate statistical data, you can create reports with graphs. There is an adequate amount of flexibility for changing the format, the type of graphs, etc."
"The product is very flexible."
"It is enterprise-wide accessible. So, it is very helpful for all the employees in our bank. They can log in and do their risk management activities. It has a few inbuilt modules that are helpful for doing risk management activities, such as issue management, risk identification, risk assessment, and policy exception management. It also has some inbuilt workflows inside these modules. They are also helpful."
"RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."
"The stability of this solution is appropriate. You can sleep well at night, if you have this solution implemented in your environment."
"Tenable Lumin's dashboard helps me understand my vulnerabilities and which tasks I should prioritize for vulnerability remediation. Tenable creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks. Real-time threat intelligence is also helpful. They get multiple sources of intelligence and correlate the data. Lumin discovers your assets through an agent or a network scan. That's an excellent feature that I'm leveraging now to better understand where all my assets are."
"Tenable Lumin is very good because it helps organizations look for solutions and profit. It also helps organizations save time because it displays market data well."
 

Cons

"The ticket handling process could be improved."
"Slow turnaround time from support team."
"The bullet chart is the best graph for my purposes, and it should be available for inclusion in the dashboards."
"I would like to have the ability to build and maintain an inventory of personal data processing activities and assets utilizing a purpose-built taxonomy and data structure."
"Archer could be improved by having more customization. I'm not sure if the backend processes have API calls and those kinds of seamless integrations, but from the front, some of the solutions are very out-of-the-box. It's not customizable, so that could be a little problematic since you have to use their features. In terms of the backend structure, I'm not too sure because I'm not a developer—I was an end user and product owner of Archer—and I don't quite know the backend and developmental features. But since it's an out-of-the-box solution, sometimes customization was challenging and support was a little problematic because we had to reach out to them all the time."
"Initially, technical support is a little weak, and I would rate it six out of ten. The issue with initial support is that new engineers are often not as experienced."
"When we have to do formulas or some other type of calculation in Archer, it sometimes doesn't work correctly. The fields don't display right, and we have to contact RSA Archer support to fix things. I think the calculation components are a bit complicated."
"Its customization features could be better."
"The price could be better."
"Tenable Lumin isn't that old and still needs some time to mature."
"The solution's cloud operation has issues Lumin and Tenable are not one product. The integration needs to be worked out better. There is space for improvement there."
 

Pricing and Cost Advice

"The initial purchase is cheap. You pay a nominal price to start then renew the license annually. You also must buy a license for each module. I'm not too fond of that aspect of the licensing model. You buy the elephant and then spend more money to feed the elephant."
"As I am a developer and responsible for providing production support, I do not have personal knowledge of the pricing. However, my colleagues claim that it is very expensive in comparison with other tools."
"The solution is not at all a cheap product."
"The license is costly for the solution, but the remaining set up and maintenance is quite cheaper."
"The solution’s pricing is moderate."
"Fairly highly-priced, especially for smaller companies."
"The pricing is okay. The licensing costs are very reasonable; it is very affordable to us."
"It is not expensive. It is reasonable. We only pay for the licensing."
"The price could be better."
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
882,160 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Insurance Company
12%
Manufacturing Company
8%
Government
5%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise6
Large Enterprise25
No data available
 

Questions from the Community

What needs improvement with RSA Archer?
While it provides benefits in terms of security, the pricing is a bit higher than customers typically expect. It would be helpful if RSA Archer had the capability for two-way integration because, i...
What is your primary use case for RSA Archer?
Regarding the compliance, risk, and governance tools, I am comfortable discussing the tools in the GRC category. The specific module from ServiceNow is the ServiceNow Compliance, Risk, and Governan...
What advice do you have for others considering RSA Archer?
I have been in touch with about three companies who use RSA Archer actively in the compliance area. These companies use RSA Archer for nearly all purposes, including governance, internal risk, and ...
Ask a question
Earn 20 points
 

Comparisons

 

Also Known As

Archer
Lumin
 

Overview

 

Sample Customers

T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Information Not Available
Find out what your peers are saying about RSA Archer vs. Tenable Lumin and other solutions. Updated: December 2025.
882,160 professionals have used our research since 2012.